Senior Manager/Chief Manager – Application security & DevSecOps

Recruitment for the role of Senior Manager/Chief Manager Application security & DevSecOpsAbout GeMGovernment eMarketplace (GeM) is a unified digital platform that facilitates end-to-end procurement of goods and services by various government departments, organizations, and public sector undertakings (PSUs). Our Honourable Prime Ministers concerted efforts to harness the power of digital platforms to achieve Minimum Government, Maximum Governance led to the genesis of GeM in 2016.GeM provides a paperless, cashless and contactless ecosystem for government buyers to directly purchase products and services from pan-India sellers and service providers through an online platform. GeM covers the entire gamut of procurement process, right from vendor registration and item selection by buyers to receipt of goods and facilitation of timely payments. GeM has envisioned to utilise the agility and speed that come along with a digital platform created with a strategic intent to reinvigorate public procurement systems and bring about a lasting change for the underserved as well as the nation.Built on the pillars of Efficiency, Transparency and Inclusivity, GeM has emerged as a digital tool in nations interest, aimed at catalyzing excellence in public procurement. To know more about us, please visit- https://gem.gov.in/You may also follow us on social media platforms like Twitter, LinkedIn, Koo App, YouTube, FacebookGeM invites applications from eligible candidates for recruitment to the following position(s) on Contractual Basis:This is a contractual engagement under the Project Management Unit (PMU) for an initial period of 5 years, extendable based on performance and organizational requirements.Eligible applicants can apply by submitting their applications including CV by 26-April-26.GeM selection committee reserves the right to relax or extend the eligibility criteria and educational qualifications. The crucial date for determining eligibility will be the last date of receipt of applications. No applications shall be entertained under any circumstances after the stipulated date. Incomplete applications without application form shall not be considered. GeM reserves the right to shortlist candidates for interview. Applicants should note that mere fulfilment of minimum eligibility criteria may not ensure consideration for short listing for interview. GeM will not entertain any correspondence on this subject and decisions of GeM will be final in all matters.Annexure IJOB DESCRIPTIONDesignation-Senior Manager/Chief Manager Application security & DevSecOpsLevel- E4/E5Job Location - New DelhiType Of Employment- Contractual Under Project Management Unit (PMU) Of GeMJob Summary We are seeking an experienced Senior Manager or Chief Manager for Application security & DevSecOps with a minimum of 8 years of experience in Application Security to drive building the security controls during SDLC, Vulnerability Management and Container Deployment and implementing controls across Cloud services like IaaS, SaaS & PaaS and Public cloud deployments. The ideal candidate will have a strong background in managing application security services such as DevSecOPs, Vulnerability Management, Container Security, Software composition analysis using COTS/ OSS solutions in either On-Prem or cloud high-performance environments, ensuring the efficiency, efficacy, and effectiveness of deployed security technologies either cloud native or third party. The candidate will also work on design and develop cloud platform-specific security policies, standards, and procedures for management group and account/subscription management and configuration.You will help to utilize public cloud infra securely in conjunction with our on-premises infrastructure and develop strategic and tactical security remediation recommendations / cyber risk roadmap to address identified security gaps. Additional responsibilities will include to define & monitor security KPIs/KRAs/SLAs internal & external.Role And ResponsibilityOwn and perform application security vulnerability management.Facilitate and support the preparation of security releases.Providing the required visibility of current state of existing vulnerabilities for complete GeM Infra and Applications universe.Building the required controls during IaaC deployments including image security, hardening and benchmarking.Liaising with product and development teams in application security and help the organization evolve its application security functions and services.Provide expertise in security tools for vulnerability assessment, penetration testing & application security.Perform vulnerability risk profiling and prioritization of vulnerabilities.Identifying, researching, validating, and exploiting various known and unknown security vulnerabilities on server and client sideDevelop capability to conduct Mobile Application Testing. Responsible for API testing, Application Testing.Oversee the development, implementation, and maintenance of vendor standard operating procedures/ run book in line with GeM policies & standards.Work closely with cross-functional teams while carrying out daily tasks.Providing communications across the organization, interfacing with stakeholders on vulnerability remediation & driving security hardening best practicesImplementing security controls for container services such as EKS, ECS in AWS based deployments.Familiarity with compliance regulations and CSA (cloud security alliance) / CIS Critical Security Controls /NIST frameworks and standards.Candidate should have excellent troubleshooting capabilities and be experienced in diagnostic/tracing tools.Any other responsibility as may be assigned from time to time.Job Qualification & RequirementsExperience RequirementsMinimum of 8 years of experience in Enterprise Security and Cloud Security.At least 3 years of experience in DevSecOps and Application Security for cloud security technologies.Lead application vulnerability scanning and penetration testing remediation, discover security exposures and develop mitigation plans.Responsible for Driving Secure by design initiatives in the organization & mentor delivery teams with right security controls to protect customer data.Responsible for application security reviews including Threat modelling, Code review and manual, Static & dynamic testing, code reviews across all Platforms.Automating the security controls during CI/CD Pipeline gaining visibility into security threats applicable by scanning images / registries, flag vulnerabilities, identify / prevent lateral movement in Container environment.Shall be able to identify the drifts during container deployment.Define data security controls for On-Prem / Cloud & Container deployments (on Open source/Off the shelf). Have detailed experience of handling SSL, PKI based encryption of data at rest, in motion and in use.Experience in building cloud security controls in open-source Container Environment (such as Kubernetes) either deployed in On-prem or public cloud. Strong knowledge of CI/CD Pipeline deployments.Responsible for development of automated security testing to validate that secure coding best practices are being used.Understand and implement best practices for base lining / hardening the heterogeneous environment (such as servers / VM's / Micro services).Manage integration with vulnerability check tools such as Static Code Analysis, Dynamic Code Analysis and Software Composition Analysis tools.Monitor vendor SLAs, perform regular review with vendor management and report to GeM leadership.Maintaining current knowledge and understanding of the threat landscape and emerging security threats and vulnerabilities.Education RequirementsBachelor of engineering (B.E.) or Bachelor of Technology (B.Tech.) or Master of Computer Application (MCA) from a recognized UniversityGood To Have SkillsExcellent analytical and problem-solving abilities.Effective communication and interpersonal skills.Familiarity with industry-standard tools and technologies.Proven experience in building and maintaining CI/CD pipelines for efficient software releases.CI/CD delivery using configuration management tools such as GitHub, VSTS, Ansible, Puppet, Chef, Salt, Jenkins, Maven, etc.Rich experience in Micro services Architecture, experience in designing, deploying and maintaining micro services architecture in AWS.Understanding of Cloud Security technologies and experience in e-commerce domain will be an added advantage.Vendor / contract management of IT partners through SLAs, KPIs.Knowledge of security and compliance requirements.Exposure to agile methodologies and strong understanding of Project Management processes.Having good understanding of Procurement processesEnsure to share and update the Change Request documentation.Strong analytical and problem-solving skills, with the ability to evaluate complex systems and make data-driven decisions.Experience with Dash boarding and reporting ManagementGood Communication skills.

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...